[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-50136-1

Platform: cpe:/o:apple:mac_os_13Date: (C)2024-04-17   (M)2024-04-17



Starting with macOS 10.15, Apple has provided a control which permits a user to share Apple downloaded content on all Apple devices that are signed in with the same Apple ID. This allows users to share downloaded Movies, Music, or TV shows with other controlled macOS, iOS and iPadOS devices, as well as photos with Apple TVs. With this capability, guest users can also use media downloaded on the computer. The recommended best practice is not to use the computer as a server, but to utilize Apple's cloud storage in order to download and use content stored there if content stored with Apple is used on multiple devices. Rationale:Disabling Media Sharing reduces the remote attack surface of the system. Impact:Media Sharing allows for pre-downloaded content on a Mac to be available to other Apple devices on the same network. Leaving this disabled forces device users to stream or download content from each Apple authorized device. This sharing could even allow unauthorized devices on the same network media access. Remediation: Run the following command to disable Media Sharing: $ /usr/bin/sudo -u <username> /usr/bin/defaults write com.apple.amp.mediasharingd home-sharing-enabled -int 0 example: $ sudo -u test2 /usr/bin/defaults write com.apple.amp.mediasharingd home-sharing-enabled -int 0


Parameter:

[Yes/No]


Technical Mechanism:

Run the following command to disable Media Sharing: $ /usr/bin/sudo -u username /usr/bin/defaults write com.apple.amp.mediasharingd home-sharing-enabled -int 0

CCSS Severity:CCSS Metrics:
CCSS Score : 8.0Attack Vector: ADJACENT_NETWORK
Exploit Score: 2.1Attack Complexity: LOW
Impact Score: 5.9Privileges Required: LOW
Severity: HIGHUser Interaction: NONE
Vector: AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HScope: UNCHANGED
 Confidentiality: HIGH
 Integrity: HIGH
 Availability: HIGH
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:99088


OVAL    1
oval:org.secpod.oval:def:99088
XCCDF    1
xccdf_org.secpod_benchmark_general_Mac_OS_13

© SecPod Technologies